• bitcoinBitcoin (BTC) $ 85,370.00
  • ethereumEthereum (ETH) $ 2,753.65
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.00
  • bnbBNB (BNB) $ 816.31
  • usd-coinUSDC (USDC) $ 0.999704
  • tronTRON (TRX) $ 0.276340
  • staked-etherLido Staked Ether (STETH) $ 2,747.37
  • dogecoinDogecoin (DOGE) $ 0.133467
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • cardanoCardano (ADA) $ 0.376914
  • whitebitWhiteBIT Coin (WBT) $ 57.42
  • wrapped-stethWrapped stETH (WSTETH) $ 3,352.97
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 84,950.00
  • bitcoin-cashBitcoin Cash (BCH) $ 515.12
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,986.18
  • usdsUSDS (USDS) $ 0.999775
  • leo-tokenLEO Token (LEO) $ 9.82
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • chainlinkChainlink (LINK) $ 11.91
  • hyperliquidHyperliquid (HYPE) $ 29.69
  • wethWETH (WETH) $ 2,745.31
  • stellarStellar (XLM) $ 0.228260
  • moneroMonero (XMR) $ 395.26
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • wrapped-eethWrapped eETH (WEETH) $ 2,972.86
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 85,096.00
  • litecoinLitecoin (LTC) $ 75.89
  • zcashZcash (ZEC) $ 339.78
  • hedera-hashgraphHedera (HBAR) $ 0.131691
  • avalanche-2Avalanche (AVAX) $ 12.72
  • suiSui (SUI) $ 1.32
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • daiDai (DAI) $ 0.999498
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.154091
  • susdssUSDS (SUSDS) $ 1.09
  • paypal-usdPayPal USD (PYUSD) $ 0.999893
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • usdt0USDT0 (USDT0) $ 0.999781
  • crypto-com-chainCronos (CRO) $ 0.100007
  • the-open-networkToncoin (TON) $ 1.47
  • uniswapUniswap (UNI) $ 5.53
  • polkadotPolkadot (DOT) $ 2.00
  • mantleMantle (MNT) $ 0.970251
  • canton-networkCanton (CC) $ 0.079261
  • usd1-wlfiUSD1 (USD1) $ 0.999713
  • aaveAave (AAVE) $ 164.56
  • bittensorBittensor (TAO) $ 258.13
  • bitget-tokenBitget Token (BGB) $ 3.44
  • memecoreMemeCore (M) $ 1.38
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • tether-goldTether Gold (XAUT) $ 4,227.73
  • falcon-financeFalcon USD (USDF) $ 0.997207
  • nearNEAR Protocol (NEAR) $ 1.61
  • okbOKB (OKB) $ 97.04
  • ethereum-classicEthereum Classic (ETC) $ 12.87
  • internet-computerInternet Computer (ICP) $ 3.67
  • pi-networkPi Network (PI) $ 0.225820
  • rainRain (RAIN) $ 0.007893
  • aster-2Aster (ASTER) $ 0.924073
  • ethenaEthena (ENA) $ 0.239426
  • jito-staked-solJito Staked SOL (JITOSOL) $ 155.13
  • pepePepe (PEPE) $ 0.000004
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,753.57
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.45
  • solanaSolana (SOL) $ 124.54
  • htx-daoHTX DAO (HTX) $ 0.000002
  • pump-funPump.fun (PUMP) $ 0.002673
  • ondo-financeOndo (ONDO) $ 0.452206
  • pax-goldPAX Gold (PAXG) $ 4,249.09
  • kaspaKaspa (KAS) $ 0.051462
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • quant-networkQuant (QNT) $ 93.62
  • aptosAptos (APT) $ 1.83
  • usdtbUSDtb (USDTB) $ 1.00
  • worldcoin-wldWorldcoin (WLD) $ 0.560594
  • bfusdBFUSD (BFUSD) $ 0.999300
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999642
  • ripple-usdRipple USD (RLUSD) $ 0.999433
  • global-dollarGlobal Dollar (USDG) $ 0.999811
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.117599
  • kucoin-sharesKuCoin (KCS) $ 9.43
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • hash-2Provenance Blockchain (HASH) $ 0.023149
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,152.72
  • wbnbWrapped BNB (WBNB) $ 816.58
  • algorandAlgorand (ALGO) $ 0.129441
  • official-trumpOfficial Trump (TRUMP) $ 5.67
  • skySky (SKY) $ 0.049309
  • gatechain-tokenGate (GT) $ 9.61
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • binance-staked-solBinance Staked SOL (BNSOL) $ 135.71
  • cosmosCosmos Hub (ATOM) $ 2.20
  • arbitrumArbitrum (ARB) $ 0.187893
  • flare-networksFlare (FLR) $ 0.013341
  • filecoinFilecoin (FIL) $ 1.46
  • vechainVeChain (VET) $ 0.012089
  • ignition-fbtcFunction FBTC (FBTC) $ 84,878.00
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,903.29
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 85,084.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 85,112.00
  • xdce-crowd-saleXDC Network (XDC) $ 0.050145
  • nexoNEXO (NEXO) $ 0.928384
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,934.06
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.91
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.996505
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 29.86
  • render-tokenRender (RENDER) $ 1.53
  • ousgOUSG (OUSG) $ 113.47
  • sei-networkSei (SEI) $ 0.121142
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.24
  • story-2Story (IP) $ 2.22
  • bonkBonk (BONK) $ 0.000009
  • morphoMorpho (MORPHO) $ 1.33
  • jupiter-exchange-solanaJupiter (JUP) $ 0.222674
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 84,926.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,924.61
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,971.73
  • clbtcclBTC (CLBTC) $ 84,904.00
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999704
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999761
  • usdaiUSDai (USDAI) $ 0.999586
  • dashDash (DASH) $ 47.87
  • beldexBeldex (BDX) $ 0.080052
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 143.47
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.228617
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.009467
  • starknetStarknet (STRK) $ 0.118928
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,840.91
  • spx6900SPX6900 (SPX) $ 0.588996
  • usual-usdUsual USD (USD0) $ 0.997613
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.829042
  • curve-dao-tokenCurve DAO (CRV) $ 0.380575
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,744.86
  • myx-financeMYX Finance (MYX) $ 2.78
  • tbtctBTC (TBTC) $ 84,512.00
  • aerodrome-financeAerodrome Finance (AERO) $ 0.589586
  • optimismOptimism (OP) $ 0.279694
  • usddUSDD (USDD) $ 0.999852
  • lido-daoLido DAO (LDO) $ 0.569957
  • msolMarinade Staked SOL (MSOL) $ 167.71
  • injective-protocolInjective (INJ) $ 5.08
  • blockstackStacks (STX) $ 0.276877
  • newton-projectAB (AB) $ 0.005516
  • true-usdTrueUSD (TUSD) $ 0.996468
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 2,460.42
  • tezosTezos (XTZ) $ 0.460922
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • the-graphThe Graph (GRT) $ 0.045440
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,754.99
  • telcoinTelcoin (TEL) $ 0.005048
  • celestiaCelestia (TIA) $ 0.553995
  • merlin-chainMerlin Chain (MERL) $ 0.436738
  • ultimaUltima (ULTIMA) $ 4,606.13
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • ether-fiEther.fi (ETHFI) $ 0.725354
  • justJUST (JST) $ 0.043412
  • kaiaKaia (KAIA) $ 0.073934
  • lorenzo-wrapped-bitcoinLorenzo Wrapped Bitcoin (ENZOBTC) $ 90,454.00
  • gtethGTETH (GTETH) $ 2,750.84
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • ghoGHO (GHO) $ 0.999083
  • stader-ethxStader ETHx (ETHX) $ 2,952.05
  • usdbUSDB (USDB) $ 1.02
  • flokiFLOKI (FLOKI) $ 0.000042
  • bitcoin-svBitcoin SV (BSV) $ 20.19
  • iotaIOTA (IOTA) $ 0.096630
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,901.78
  • pendlePendle (PENDLE) $ 2.41
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.39
  • bittorrentBitTorrent (BTT) $ 0.00000040
  • sun-tokenSun Token (SUN) $ 0.020208
  • pyth-networkPyth Network (PYTH) $ 0.067134
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.919708
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000002
  • sbtc-2sBTC (SBTC) $ 85,453.00
  • apenftAINFT (NFT) $ 0.00000038
  • basic-attention-tokenBasic Attention (BAT) $ 0.248125
  • doublezeroDoubleZero (2Z) $ 0.106382
  • olympusOlympus (OHM) $ 22.48
  • swethSwell Ethereum (SWETH) $ 3,009.26
  • the-sandboxThe Sandbox (SAND) $ 0.139239
  • conflux-tokenConflux (CFX) $ 0.069145
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,036.29
  • compound-governance-tokenCompound (COMP) $ 36.17
  • heliumHelium (HNT) $ 1.88
  • sonic-3Sonic (S) $ 0.093108
  • plasmaPlasma (XPL) $ 0.175687
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 84,971.00
  • flowFlow (FLOW) $ 0.213144
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.133201
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,745.50
  • euro-coinEURC (EURC) $ 1.16
  • dogwifcoindogwifhat (WIF) $ 0.334683
  • jasmycoinJasmyCoin (JASMY) $ 0.006624
  • kinesis-goldKinesis Gold (KAU) $ 135.96
  • usxUSX (USX) $ 1.00
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 15.65

North Korean Hackers Deploy Blockchain-Based Tools in Expanding Global Cyber Campaign

0 26

North Korean Hackers Deploy Blockchain-Based Tools in Expanding Global Cyber Campaign

North Korea-linked threat actors are escalating their cyber operations using decentralized and evasive malware tools, according to new findings from Cisco Talos and Google Threat Intelligence Group.

The campaigns aim to steal cryptocurrency, infiltrate networks, and evade detection through sophisticated job recruitment scams.

Evolving Malware Techniques Reflect Expanding Capabilities

Cisco Talos researchers identified an ongoing campaign by the North Korean group Famous Chollima. The group has used two complementary malware strains, BeaverTail and OtterCookie. These programs, traditionally used for credential theft and data exfiltration, have now evolved to integrate new functionalities and closer interoperation.

In a recent incident involving an organization in Sri Lanka, attackers lured a job seeker into installing malicious code disguised as part of a technical evaluation. Even though the organization itself was not a direct target, Cisco Talos analysts also observed a keylogging and screenshotting module linked to OtterCookie, which highlights the broader risk to individuals involved in fake job offers. This module covertly recorded keystrokes and captured desktop images, automatically transmitting them to a remote command server.

Cisco Talos reports that the North Korean group Famous Chollima is using a new JavaScript module combining BeaverTail and OtterCookie for keylogging and screenshots, targeting job seekers through fake offers and malicious Node.js packages. #CyberSecurity https://t.co/vRba8a3GcT

— Cyber_OSINT (@Cyber_O51NT) October 16, 2025

This observation underscores the ongoing evolution of North Korea-aligned threat groups and their focus on social engineering techniques to compromise unsuspecting targets.

Blockchain Used as a Command Infrastructure

Google’s Threat Intelligence Group (GTIG) identified an operation by a North Korea-linked actor, UNC5342. The group used a new malware called EtherHiding. This tool hides malicious JavaScript payloads on a public blockchain, turning it into a decentralized command and control (C2) network.

By using blockchain, attackers can change malware behavior remotely without traditional servers. Law enforcement takedowns become much harder. Furthermore, GTIG reported that UNC5342 applied EtherHiding in a social engineering campaign called Contagious Interview, which had been previously identified by Palo Alto Networks, demonstrating the persistence of North Korea-aligned threat actors.

What is EtherHiding?
It’s a novel technique where the attackers embed malicious payloads (like JADESNOW and INVISIBLEFERRET malware) within smart contracts on public blockchains (like BNB Smart Chain and Ethereum). https://t.co/AyKeSuPyWW pic.twitter.com/we4NV2PTu5

— blackorbird (@blackorbird) October 16, 2025

Targeting Job Seekers to Steal Cryptocurrency and Data

According to Google researchers, these cyber operations typically begin with fraudulent job postings aimed at professionals in the cryptocurrency and cybersecurity industries. Victims are invited to participate in fake assessments, during which they are instructed to download files embedded with malicious code.

The infection process often involves multiple malware families, including JadeSnow, BeaverTail, and InvisibleFerret. Together, they let attackers access systems, steal credentials, and deploy ransomware efficiently. The end goals range from espionage and financial theft to long-term network infiltration.

Cisco and Google have published indicators of compromise (IOCs) to help organizations detect and respond to ongoing North Korea-linked cyber threats. These resources provide technical details for identifying malicious activity and mitigating potential breaches. Researchers warn that the integration of blockchain and modular malware will likely continue to complicate global cybersecurity defense efforts.

The post North Korean Hackers Deploy Blockchain-Based Tools in Expanding Global Cyber Campaign appeared first on BeInCrypto.

Source

Leave A Reply

Your email address will not be published.